| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2023-33321 | WordPress EventPrime plugin <= 2.8.6 - Sensitive Data Exposure | Metagauss | EventPrime | Medium | 5.3 | 2024-05-17 06:45:49 | Deep Dive |
| CVE-2024-29776 | WordPress EventPrime plugin <= 3.3.9 - Cross Site Scripting (XSS) vulnerability | Metagauss | EventPrime | Medium | 5.9 | 2024-03-27 12:48:27 | Deep Dive |
| CVE-2024-24832 | WordPress EventPrime plugin <= 3.3.9 - Broken Access Control vulnerability | Metagauss | EventPrime | High | 8.2 | 2024-03-23 14:53:19 | Deep Dive |
| CVE-2024-1126 | EventPrime – Events Calendar, Bookings and Tickets <= 3.4.2 - Missing Authorization to Authenticated (Subscriber+) Attendee List Retrieval | metagauss | EventPrime – Events Calendar, Bookings and Tickets | Medium | 4.3 | 2024-03-13 15:27:17 | Deep Dive |
| CVE-2024-1321 | EventPrime – Events Calendar, Bookings and Tickets <= 3.4.2 - Unauthenticated Booking Payment Bypass | metagauss | EventPrime – Events Calendar, Bookings and Tickets | Medium | 5.3 | 2024-03-13 15:26:57 | Deep Dive |
| CVE-2024-1127 | EventPrime – Events Calendar, Bookings and Tickets <= 3.4.1 - Missing Authorization to Authenticated (Subscriber+) Event Export | metagauss | EventPrime – Events Calendar, Bookings and Tickets | Medium | 4.3 | 2024-03-13 15:26:44 | Deep Dive |
| CVE-2024-1320 | EventPrime – Events Calendar, Bookings and Tickets <= 3.4.3 - Unauthenticated Stored Cross-Site Scripting | metagauss | EventPrime – Events Calendar, Bookings and Tickets | Medium | 6.5 | 2024-03-09 07:01:10 | Deep Dive |
| CVE-2024-1125 | EventPrime – Events Calendar, Bookings and Tickets <= 3.4.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion | metagauss | EventPrime – Events Calendar, Bookings and Tickets | Medium | 5.4 | 2024-03-09 07:01:10 | Deep Dive |
| CVE-2024-1123 | EventPrime – Events Calendar, Bookings and Tickets <= 3.4.2 - Missing Authorization to Arbitrary Post Overwrite | metagauss | EventPrime – Events Calendar, Bookings and Tickets | Medium | 6.5 | 2024-03-09 07:01:09 | Deep Dive |
| CVE-2024-1124 | EventPrime – Events Calendar, Bookings and Tickets <= 3.4.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Sending | metagauss | EventPrime – Events Calendar, Bookings and Tickets | Medium | 4.3 | 2024-03-09 07:01:05 | Deep Dive |
| CVE-2023-6447 | EventPrime < 3.3.6 - Unauthenticated Event Access | Unknown | EventPrime | 中危 | - | 2024-01-22 19:14:30 | Deep Dive |
| CVE-2023-4252 | EventPrime <= 3.2.9 - Booking Pricing Bypass | Unknown | EventPrime | 高危 | - | 2023-11-27 16:22:00 | Deep Dive |
| CVE-2023-4250 | EventPrime < 3.2.0 - Reflected XSS | Unknown | EventPrime | 中危 | - | 2023-10-31 13:54:47 | Deep Dive |
| CVE-2023-4251 | EventPrime < 3.2.0 - Booking Creation via CSRF | Unknown | EventPrime | 中危 | - | 2023-10-31 13:54:46 | Deep Dive |
| CVE-2023-5519 | EventPrime < 3.2.0 - Booking Creation via CSRF | Unknown | EventPrime | 中危 | - | 2023-10-31 13:54:44 | Deep Dive |
| CVE-2023-5238 | EventPrime < 3.2.0 - Reflected HTML Injection on keyword parameter | Unknown | EventPrime | 中危 | - | 2023-10-31 13:54:44 | Deep Dive |
| CVE-2023-45637 | WordPress EventPrime Plugin <= 3.1.5 is vulnerable to Cross Site Scripting (XSS) | EventPrime | EventPrime – Events Calendar, Bookings and Tickets | High | 7.1 | 2023-10-24 11:02:56 | Deep Dive |
| CVE-2023-35884 | WordPress EventPrime Plugin <= 3.0.5 is vulnerable to Cross Site Scripting (XSS) | EventPrime | EventPrime | High | 7.1 | 2023-06-20 06:50:34 | Deep Dive |
| CVE-2023-33326 | WordPress EventPrime Plugin <= 2.8.6 is vulnerable to Cross Site Scripting (XSS) | EventPrime | EventPrime | High | 7.1 | 2023-05-28 17:42:33 | Deep Dive |